Ad

CVE-2026-28786

MEDIUM CVSS 3.1: 4.3 EPSS 0.02%
Updated Mar 30, 2026
Openwebui
Parameter Value
CVSS 4.3 (MEDIUM)
Affected Versions before 0.8.6
Fixed In 0.8.6
Type CWE-209 (Information Exposure Through Error Message), CWE-22 (Path Traversal)
Vendor Openwebui
Public PoC No

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to version 0.8.6, an unsanitized filename field in the speech-to-text transcription endpoint allows any authenticated non-admin user to trigger a `FileNotFoundError` whose message — including the server's absolute `DATA_DIR` path — is returned verbatim in the HTTP 400 response body, confirming information disclosure on all default deployments. Version 0.8.6 patches the issue.

Attack Parameters

Attack Vector
Network
Can be exploited remotely
Attack Complexity
Low
Easy to exploit
Privileges Required
Low
Basic privileges needed
User Interaction
None
No user interaction needed

Impact Assessment

Confidentiality
Low
Partial data leak
Integrity
None
No data modification
Availability
None
No disruption

CVSS Vector v3.1

Vulnerable Products 1

Configuration From (including) Up to (excluding)
Openwebui Open_Webui
cpe:2.3:a:openwebui:open_webui:*:*:*:*:*:*:*:*
0.8.6